- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,762
SecNumCloud checks 1200 requirements - only here are processors with Management Engine remained behind brackets.

Europe spends billions of euros on sovereign clouds to store and process data less dependent on U.S. companies and U.S. laws. But under European certificates, the Intel or AMD processor often remains. Inside such chips there are control subsystems that are below the operating system and do not obey conventional protections.
More than 2 billion euros are already being spent on sovereign cloud infrastructure in Europe. The IPCEI-CIS program funds new generation services and data centers, and the French SecNumCloud checks operators by a large set of technical, organizational and legal requirements. Qualifications should protect customers from extraterritorial laws when foreign authorities are trying to obtain information through companies under someone else’s jurisdiction.
The main gap appears below the level of cloud service. SecNumCloud evaluates management, architecture, encryption, access control and reaction to incidents. Processors under this infrastructure usually remain out of check, so the server can get a European certificate, but its central chip will still be designed by an American company.
Intel has such a layer is called Management Engine, more precisely Converged Security and Management Engine, CSME. The AMD has a similar role in the Platform Security Processor, PSP. Researchers often refer to this level of Ring -3: the operating system and the hypervisor are higher, so security agents on the server do not see everything that the built-in control mechanism does.
CSME does not apply to Windows or Linux. It is a separate microcontroller inside the platform with its memory, watches, access to devices and network functions. Computer Architecture professor John Goodacre, a former head of the British program Digital Security by Design worth 200 million pounds, describes the Intel Management Engine as a separate computer inside the main machine. According to him, such a component can use the MAC address and the IP address of the host, so the firewall perceives its exchange as the usual traffic of the server or laptop.
This architecture has a normal administrative task. Intel Active Management Technology, or AMT, helps to remotely serve large parks of devices: connect to the keyboard, screen and mouse, redirect drives, use Serial over LAN, SOL, and turn on or off the machines. On customized systems, the technology uses TCP ports 16992, 16993, 16994 and 16995, although on new Intel platforms gradually moves away from unsafe connectivity options in favor of TLS. For corporate support, this is convenient, but in the sovereign cloud there is a control channel below the operating system.
The practical risk has already been described by Microsoft. In 2017, the company spoke about the attack of the group PLATINUM, which was associated with the state level. The attackers used Intel Serial over LAN as a hidden data output channel: the flow passed through the Management Engine and the off-lockwalk of the network adapter before the launch of the usual TCP/IP stack. Local firewall, protective agents and monitoring on the infected machine did not notice the exchange. The group did not look for an error in the code, but used the regular function AMT. In well-known cases, there was enough remote administration and factory ligament admin with an empty password.
Gudakur analyzed similar scenarios in a 37-page assessment for information security executives who check Intel vPro on corporate networks. Its output sounds hard: the device with unlimited Management Engine opens the class of attacks bypassing the host’s defense. BitLocker, input via FODO2, EDR, local firewall and corporate VPN are hit.
The Management Engine can remain active even when the device looks off. Laptop owners know a similar situation: the car lies idle for several weeks, and the next start the battery is almost discharged. On modern thin models, the Modern Standby mode, or the modern mode, does not mean complete de-energizing all subsystems. Some of the components of the system-on-crystal remains in a low-energy state, and the constant consumption of about 100-200 mW in a few weeks can noticeably plant the battery at 55 Wh.
In the work of Gudakra, the risk with the wireless network is separately disassembled. The radio module can wait for the Wake-on-Wireless-LAN signal, and this behavior is set by the firmware. If it was changed during delivery, the external status of the food does not guarantee anything. The laptop is able to lie in a bag, look off and at the same time connect to a hostile network without the owner’s knowledge.
Professor EURECOM Aurélen Francisco Collionn has been studying attacks through firmware for many years. Together with colleagues, he created a working backdoor in the hard drive code and showed how the drive can imperceptibly output data through hidden channels. Three months after the academic presentation, Snowden’s documents revealed the NSA ANT catalog, which described a similar opportunity already applied in practice. Therefore, Francillon does not reject the risk of Intel Management Engine: according to his estimation, ME, BMC and other low-level components can work as backdoors. But the main question he sees in another: is it really possible to get to such a path with good network insulation and strict control of administration.
The transition from Intel to AMD itself does not solve the problem. On April 14, 2026, researchers showed a Fabricked attack against AMD SEV-SNP’s confidential computing technology. The software exploit worked in 100% of the attempt, and Platform Security Processor was vulnerable to similar compromise.
On the server equipment next to this theme there is another component: BMC, the baseboard control controller. Through it, administrators work with a server outside the main operating system. In Intel, the server version of Management Engine is called Server Platform Services, SPS, and BMC often serves as a network input to these features. Francillon considers such a controller a more visible threat to the clouds: with a successful attack, an attacker can remotely reinstall the system or completely compromise the machine.
Legal risks increase the technical problem. CLOUD Act, adopted in 2018, gave the US authorities the opportunity to demand U.S. information from U.S. companies, even if it is stored outside the country. Section 702 of the FISA Act allows intelligence agencies to oblige American individuals and organizations to help with access to communications. But RISAA 2024 has expanded the definition of an electronic service provider so that it can be subject to companies with access to equipment for the transmission or storage of messages. Intel and AMD could potentially receive secret orders banning disclosure and the obligation to cooperate with U.S. intelligence.
The technical pathway for such access is already built into the platform: the privileged environment inside the processor is connected to the network and hidden from the host operating system. The SecNumCloud qualified operator can be legally separated from U.S. customer data requirements. The server chip still remains a company product from the United States. The RISAA’s two-year term for Section 702 was expired on April 20, 2026, but Congress extended the powers for another 45 days while the reforms are being discussed. Even the amendments to the law will not change the architecture of already released processors.
French SecNumCloud has originally grown out of cybersecurity policy. The national agency ANSSI appeared in 2009, and the first version of the qualification was released in July 2014, shortly after Snowden’s revelations. The scheme described architecture, encryption, access control and response to incidents, but did not solve the issue of the owner of the basic infrastructure. After CLOUD Act, the context has changed. In version 3.2, published in 2022, there was Chapter 19 with requirements against extraterritorial access: the service must be served by operators from the EU, the non-European side does not get access to customer data, and the provider is obliged to work autonomously without external interference.
In December 2025, the S3NS, a joint venture between the French Thales and Google Cloud, received the SecNumCloud qualification for a hybrid cloud on Google Cloud Platform technologies under French control. After that, a dispute began: some saw a working version of sovereignty through European governance, others considered the project to be American technology under the French flag. But the discussion almost did not touch upon a deeper question: whether the scheme checks the processors on which the entire infrastructure works.
Francillon knows this problem from both sides: he is part of the working group of the French Technology Academy for Cloud Security and at the same time studying backdoors in firmware. According to him, SecNumCloud does not contain a direct requirement that would close Intel Management Engine or AMD Platform Security Processor. The scheme was not created as a detailed instruction to protect the hardware layer. It requires modulating threats, reducing risks and controlling administrative gateways, including external technical support channels.
The head of ANSSI Vincent Strubelle in January 2026 also outlined the boundaries of SecNumCloud. According to his position, all cloud services depend on electronic components, the development and updates of which Europe does not control completely. If European operators are once cut off from U.S. or Chinese technology, the effects will hit the entire industry, not just hybrid clouds. Strubelle describes the qualification as a cybersecurity tool, not industrial policy: it protects against extraterritorial enforcement and disconnection of services, but does not replace someone else’s hardware base.
Consolidity disputes often recall OpenTitan, an open secure Google element that is used on the company’s server hardware and is part of the S3NS infrastructure. But it does not replace the main processor. This is a separate small chip close to the role of TPM: protects keys, signs operations and helps to carry out certification. Linux, applications and cloud loads on it do not run. OpenTitan can take some of the trust beyond Intel ME, but does not remove the ME itself and does not solve the AMD PSP problem.
ANSSI’s position on sensitive computing, published in October 2025, also does not close the hardware gap. The document says that Intel SGX, Intel TDX and AMD SEV-SNP are not enough to protect the entire system and meet the requirements of SecNumCloud 3.2. The physical access of the attacker to the equipment and attacks on the supply chain are outside the safety objectives of the manufacturers. With Management Engine, the situation is more complicated: the threat can come over the network, and not through direct contact with the server.
Francillon believes that competent exploitation makes such an attack very expensive. Network isolation, monitoring, separation of administrative gateways and control of external support create a protective perimeter. Backdoor may exist, but only players of the state level with serious resources will be able to get to it. For most threat models, in his estimation, such a reduction in risk is sufficient. The Hrudock looks harder: if the Management Engine installs an encrypted TLS connection to the attacker server through the port 443, the external firewall will see the usual HTTPS traffic. Filtering will reduce the area of the attack, but will not remove the channel completely.
Gudakr attributes the remaining risk to the level of Tier 3. Under this term, he understands civil cyber services that are able to interfere in firmware during delivery, issue incorrect certificates through national certification centers, change equipment at customs or in courier nodes. Famous materials on NSA Tailored Access Operations showed that the interception of supply chains was a working tool for such structures, and implants in BIOS and low-level code were considered preferable to malicious files on the disk.
Real enterprise networks show that low-level vulnerabilities have been living for years. According to Eclypsium from working environments, about 72% of the observed devices remained vulnerable to INTEL-SA-003991 years after the problem was disclosed, and 61% to INTEL-SA-002995. The same materials mentioned the Conti group: the operators of the extortionist software were developing a demonstration code for the operation of Intel ME to install persistent implants in the firmware.
The dispute between Francisco and Gudacro is not about whether there is a problem. Both recognize the risk of Intel ME and AMD PSP, as well as the inability to close such a class of threats with a regular update on top of the operating system. Difference in assessing practical danger. One believes that good operational measures leave the way only for a very strong opponent. Another insists that the network and legal channel are preserved, so the sovereign cloud should take it into account directly in the threat model.
There is no quick replacement. RISC-V, an open architecture of processors, supporters of European technological independence are called a long-term exit, but the competitive performance in data centers is still far away. Francillon evaluates the path at the decade. Arm’s history confirms caution: almost 20 years have passed from the first server attempts to noticeable presence in data centers.
For customers, the main question is simply: how the provider takes into account Intel Management Engine, AMD Platform Security Processor and BMC in the threat model. The answer will show whether the supplier considers the hardware layer to be a zone of responsibility or implemented measures that reduce the risk, albeit not completely removed it.

Europe spends billions of euros on sovereign clouds to store and process data less dependent on U.S. companies and U.S. laws. But under European certificates, the Intel or AMD processor often remains. Inside such chips there are control subsystems that are below the operating system and do not obey conventional protections.
More than 2 billion euros are already being spent on sovereign cloud infrastructure in Europe. The IPCEI-CIS program funds new generation services and data centers, and the French SecNumCloud checks operators by a large set of technical, organizational and legal requirements. Qualifications should protect customers from extraterritorial laws when foreign authorities are trying to obtain information through companies under someone else’s jurisdiction.
The main gap appears below the level of cloud service. SecNumCloud evaluates management, architecture, encryption, access control and reaction to incidents. Processors under this infrastructure usually remain out of check, so the server can get a European certificate, but its central chip will still be designed by an American company.
Intel has such a layer is called Management Engine, more precisely Converged Security and Management Engine, CSME. The AMD has a similar role in the Platform Security Processor, PSP. Researchers often refer to this level of Ring -3: the operating system and the hypervisor are higher, so security agents on the server do not see everything that the built-in control mechanism does.
CSME does not apply to Windows or Linux. It is a separate microcontroller inside the platform with its memory, watches, access to devices and network functions. Computer Architecture professor John Goodacre, a former head of the British program Digital Security by Design worth 200 million pounds, describes the Intel Management Engine as a separate computer inside the main machine. According to him, such a component can use the MAC address and the IP address of the host, so the firewall perceives its exchange as the usual traffic of the server or laptop.
This architecture has a normal administrative task. Intel Active Management Technology, or AMT, helps to remotely serve large parks of devices: connect to the keyboard, screen and mouse, redirect drives, use Serial over LAN, SOL, and turn on or off the machines. On customized systems, the technology uses TCP ports 16992, 16993, 16994 and 16995, although on new Intel platforms gradually moves away from unsafe connectivity options in favor of TLS. For corporate support, this is convenient, but in the sovereign cloud there is a control channel below the operating system.
The practical risk has already been described by Microsoft. In 2017, the company spoke about the attack of the group PLATINUM, which was associated with the state level. The attackers used Intel Serial over LAN as a hidden data output channel: the flow passed through the Management Engine and the off-lockwalk of the network adapter before the launch of the usual TCP/IP stack. Local firewall, protective agents and monitoring on the infected machine did not notice the exchange. The group did not look for an error in the code, but used the regular function AMT. In well-known cases, there was enough remote administration and factory ligament admin with an empty password.
Gudakur analyzed similar scenarios in a 37-page assessment for information security executives who check Intel vPro on corporate networks. Its output sounds hard: the device with unlimited Management Engine opens the class of attacks bypassing the host’s defense. BitLocker, input via FODO2, EDR, local firewall and corporate VPN are hit.
The Management Engine can remain active even when the device looks off. Laptop owners know a similar situation: the car lies idle for several weeks, and the next start the battery is almost discharged. On modern thin models, the Modern Standby mode, or the modern mode, does not mean complete de-energizing all subsystems. Some of the components of the system-on-crystal remains in a low-energy state, and the constant consumption of about 100-200 mW in a few weeks can noticeably plant the battery at 55 Wh.
In the work of Gudakra, the risk with the wireless network is separately disassembled. The radio module can wait for the Wake-on-Wireless-LAN signal, and this behavior is set by the firmware. If it was changed during delivery, the external status of the food does not guarantee anything. The laptop is able to lie in a bag, look off and at the same time connect to a hostile network without the owner’s knowledge.
Professor EURECOM Aurélen Francisco Collionn has been studying attacks through firmware for many years. Together with colleagues, he created a working backdoor in the hard drive code and showed how the drive can imperceptibly output data through hidden channels. Three months after the academic presentation, Snowden’s documents revealed the NSA ANT catalog, which described a similar opportunity already applied in practice. Therefore, Francillon does not reject the risk of Intel Management Engine: according to his estimation, ME, BMC and other low-level components can work as backdoors. But the main question he sees in another: is it really possible to get to such a path with good network insulation and strict control of administration.
The transition from Intel to AMD itself does not solve the problem. On April 14, 2026, researchers showed a Fabricked attack against AMD SEV-SNP’s confidential computing technology. The software exploit worked in 100% of the attempt, and Platform Security Processor was vulnerable to similar compromise.
On the server equipment next to this theme there is another component: BMC, the baseboard control controller. Through it, administrators work with a server outside the main operating system. In Intel, the server version of Management Engine is called Server Platform Services, SPS, and BMC often serves as a network input to these features. Francillon considers such a controller a more visible threat to the clouds: with a successful attack, an attacker can remotely reinstall the system or completely compromise the machine.
Legal risks increase the technical problem. CLOUD Act, adopted in 2018, gave the US authorities the opportunity to demand U.S. information from U.S. companies, even if it is stored outside the country. Section 702 of the FISA Act allows intelligence agencies to oblige American individuals and organizations to help with access to communications. But RISAA 2024 has expanded the definition of an electronic service provider so that it can be subject to companies with access to equipment for the transmission or storage of messages. Intel and AMD could potentially receive secret orders banning disclosure and the obligation to cooperate with U.S. intelligence.
The technical pathway for such access is already built into the platform: the privileged environment inside the processor is connected to the network and hidden from the host operating system. The SecNumCloud qualified operator can be legally separated from U.S. customer data requirements. The server chip still remains a company product from the United States. The RISAA’s two-year term for Section 702 was expired on April 20, 2026, but Congress extended the powers for another 45 days while the reforms are being discussed. Even the amendments to the law will not change the architecture of already released processors.
French SecNumCloud has originally grown out of cybersecurity policy. The national agency ANSSI appeared in 2009, and the first version of the qualification was released in July 2014, shortly after Snowden’s revelations. The scheme described architecture, encryption, access control and response to incidents, but did not solve the issue of the owner of the basic infrastructure. After CLOUD Act, the context has changed. In version 3.2, published in 2022, there was Chapter 19 with requirements against extraterritorial access: the service must be served by operators from the EU, the non-European side does not get access to customer data, and the provider is obliged to work autonomously without external interference.
In December 2025, the S3NS, a joint venture between the French Thales and Google Cloud, received the SecNumCloud qualification for a hybrid cloud on Google Cloud Platform technologies under French control. After that, a dispute began: some saw a working version of sovereignty through European governance, others considered the project to be American technology under the French flag. But the discussion almost did not touch upon a deeper question: whether the scheme checks the processors on which the entire infrastructure works.
Francillon knows this problem from both sides: he is part of the working group of the French Technology Academy for Cloud Security and at the same time studying backdoors in firmware. According to him, SecNumCloud does not contain a direct requirement that would close Intel Management Engine or AMD Platform Security Processor. The scheme was not created as a detailed instruction to protect the hardware layer. It requires modulating threats, reducing risks and controlling administrative gateways, including external technical support channels.
The head of ANSSI Vincent Strubelle in January 2026 also outlined the boundaries of SecNumCloud. According to his position, all cloud services depend on electronic components, the development and updates of which Europe does not control completely. If European operators are once cut off from U.S. or Chinese technology, the effects will hit the entire industry, not just hybrid clouds. Strubelle describes the qualification as a cybersecurity tool, not industrial policy: it protects against extraterritorial enforcement and disconnection of services, but does not replace someone else’s hardware base.
Consolidity disputes often recall OpenTitan, an open secure Google element that is used on the company’s server hardware and is part of the S3NS infrastructure. But it does not replace the main processor. This is a separate small chip close to the role of TPM: protects keys, signs operations and helps to carry out certification. Linux, applications and cloud loads on it do not run. OpenTitan can take some of the trust beyond Intel ME, but does not remove the ME itself and does not solve the AMD PSP problem.
ANSSI’s position on sensitive computing, published in October 2025, also does not close the hardware gap. The document says that Intel SGX, Intel TDX and AMD SEV-SNP are not enough to protect the entire system and meet the requirements of SecNumCloud 3.2. The physical access of the attacker to the equipment and attacks on the supply chain are outside the safety objectives of the manufacturers. With Management Engine, the situation is more complicated: the threat can come over the network, and not through direct contact with the server.
Francillon believes that competent exploitation makes such an attack very expensive. Network isolation, monitoring, separation of administrative gateways and control of external support create a protective perimeter. Backdoor may exist, but only players of the state level with serious resources will be able to get to it. For most threat models, in his estimation, such a reduction in risk is sufficient. The Hrudock looks harder: if the Management Engine installs an encrypted TLS connection to the attacker server through the port 443, the external firewall will see the usual HTTPS traffic. Filtering will reduce the area of the attack, but will not remove the channel completely.
Gudakr attributes the remaining risk to the level of Tier 3. Under this term, he understands civil cyber services that are able to interfere in firmware during delivery, issue incorrect certificates through national certification centers, change equipment at customs or in courier nodes. Famous materials on NSA Tailored Access Operations showed that the interception of supply chains was a working tool for such structures, and implants in BIOS and low-level code were considered preferable to malicious files on the disk.
Real enterprise networks show that low-level vulnerabilities have been living for years. According to Eclypsium from working environments, about 72% of the observed devices remained vulnerable to INTEL-SA-003991 years after the problem was disclosed, and 61% to INTEL-SA-002995. The same materials mentioned the Conti group: the operators of the extortionist software were developing a demonstration code for the operation of Intel ME to install persistent implants in the firmware.
The dispute between Francisco and Gudacro is not about whether there is a problem. Both recognize the risk of Intel ME and AMD PSP, as well as the inability to close such a class of threats with a regular update on top of the operating system. Difference in assessing practical danger. One believes that good operational measures leave the way only for a very strong opponent. Another insists that the network and legal channel are preserved, so the sovereign cloud should take it into account directly in the threat model.
There is no quick replacement. RISC-V, an open architecture of processors, supporters of European technological independence are called a long-term exit, but the competitive performance in data centers is still far away. Francillon evaluates the path at the decade. Arm’s history confirms caution: almost 20 years have passed from the first server attempts to noticeable presence in data centers.
For customers, the main question is simply: how the provider takes into account Intel Management Engine, AMD Platform Security Processor and BMC in the threat model. The answer will show whether the supplier considers the hardware layer to be a zone of responsibility or implemented measures that reduce the risk, albeit not completely removed it.